Adobe InDesign Vulnerable to Heap-based Buffer Overflow
CVE-2024-20781

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
9 July 2024

Summary

Adobe InDesign Desktop has been found to possess a Heap-based Buffer Overflow vulnerability. This issue affects versions ID19.3, ID18.5.2 and earlier. An attacker can exploit this vulnerability by enticing a user to open a specially crafted malicious file, which could lead to arbitrary code execution with the permissions of the current user. To mitigate the potential risks, it is essential for users to refrain from opening untrusted or unknown files.

Affected Version(s)

InDesign Desktop 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.